Review a false ban
Which detections you can act on immediately, which need the evidence read first, and how to tell them apart.
Use the log evidence before you act. Start with the Additional Info panel, which names the detection and the value that fired it, then open any screenshot or recording attached to the ban. For most detections that is enough to tell real cheating from a false positive in under a minute.
Detections you can usually act on
These fire on something the server can prove: a value the game cannot produce, an exact match against a list you control, or a request a normal client never sends. A hit here is almost always the player, though the evidence is still worth a look when the punishment is permanent.
| Detection | Why it is hard to fire by accident |
|---|---|
AntiAimbot | Needs aim behaviour no human input produces. |
AntiSilentAim | A hit registered while the weapon was never pointed at the target. |
AntiMagicBullet | A hit with no trajectory between the muzzle and the target. |
AntiGiveWeapons | A weapon appearing in an inventory the server never put it in. |
AntiRemoveWeapons | A weapon leaving an inventory the server did not take it from. |
AntiStartResources | A client asking the server to start a resource. |
AntiStopResources | A client asking the server to stop a resource. |
AntiSpoofBulletShot | Shot data that contradicts what the game reported. |
AntiBlacklistWeapons | An exact match against a list you control. |
BlacklistEntitiesProtection | An exact model match against a list you control. |
AntiSpawnIsolatedVehicle | A vehicle created outside any normal spawn path. |
AntiDamageExploits | Damage values the game cannot produce. |
AntiSpoofedDamage | Damage attributed to a weapon that did not fire it. |
Detections to read the evidence on first
These are not unreliable, but their trigger can also be produced by your own scripts, a weak machine or a bad connection. Read the evidence and the Additional Info before you punish, and when one of them fires repeatedly on ordinary players, treat that as a config problem rather than a cheating problem.
| Detection | What the innocent explanation looks like |
|---|---|
ClipboardScanner | Matches its word list as a substring, so ordinary words hit. "sprint" contains "print". |
AntiScreenOcr | Reads text off the screen, including text your own UI drew. Ships off for this reason. |
AntiExecutor | Overlays and capture tools can look like an injector. Check the evidence before acting. |
AntiNuiTamper | The Timeout half fires when the browser layer hangs, which a weak machine does on its own. |
AntiGodmode | Tests by dealing one damage and watching. Health scripts that heal instantly look identical. |
AntiSpawnWeapons | Any custom weapon you have not registered reads as an unknown weapon appearing. |
AntiSpeedHack | Sprint modifiers, parkour scripts and vehicle ejection all produce real speed. |
AntiNoclip | Falling through unloaded map geometry looks the same as walking through it. |
AntiTeleportInVehicle | Garage scripts and vehicle resets move a player instantly on purpose. |
AntiParticleAi | Scripted effects on a busy scene can cross the spam rules without anyone cheating. |
AntiExplosionAi | Scripted explosions in a job or an event can cross the spam rules the same way. |
AiServerEventsProtection | The highest false-positive surface on any framework server. Read the event name first. |
EntitiesSpamProtection | An inventory dropping a large stash, or a garage pulling several cars, counts as spam. |
AntiResourcesInjection | On a resource older than 1.8.5.8, ox_lib triggers this legitimately. Update before trusting it. |
If you decide it was a false positive
Lift the ban from the Bans List, then fix the cause so it does not happen to the next player. The Additional Info panel almost always names something you can whitelist: the resource that created an entity, the event that was blocked, the model, or the weapon. Whitelisting that one thing is better than raising a threshold, because a threshold change weakens the detection for everybody.